Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xrorre
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
xrorre
10y ago
Here's an old XSS exploit for Roundcube from 2013: https://www.intelligentexploit.com/view-details.html?id=1696... I still use RC despite the long history of XSS attacks against it. Luckily RC uses progressive enhancem
2.
▲
by
xrorre
10y ago
I appreciate the intention of this article. Written for people only starting to change their surfing habits in light of Snowden. But the example of the tools they should use are not thought out very well. First: Freedome by F-Secure is clos
3.
▲
by
xrorre
10y ago
asdf
4.
▲
The blockchain is a threat to the distributed future of the Internet
(lasindias.com)
124 points
by
xrorre
10y ago
|
77 comments
5.
▲
Bot Family – Bot Store for Your Messengers
(botfamily.com)
3 points
by
xrorre
10y ago
|
0 comments
6.
▲
by
xrorre
10y ago
In terms of a threat model, it includes any machine which acts as a hypervisor and as the old saying goes: If you don't trust the hypervisor, how can you trust any machine running in that hypervisor? Antilogging is but one tiny compone
7.
▲
by
xrorre
10y ago
Typically we don't want the userspace to be compromised at all. An antilogger works by effectively substituting letters as they are typed. So when I type 'A', it is read as A in the kernel, but backspaced, replaced by a rando
8.
▲
by
xrorre
10y ago
You can counter this by creating a hook to scramble keys as they are typed. There are countless antiloggers out there and they're the first thing I install on any fresh distro. Why this antilogging technique is not the default in most
9.
▲
by
xrorre
10y ago
Qubes is exponetially superior to this distro. Open that PDF in a disposable Fedora sandbox, and physically disable the network plz
10.
▲
by
xrorre
10y ago
JPGs are also a lot safer as PDFs can ping remote resources using carefully hidden beacon images. Although that said, I sometimes use this to see who opened my files. I once left hundreds of these on a very popular cloud hosting provider (n
11.
▲
by
xrorre
10y ago
Zemana Antilogger is pretty sufficient for these threats, and also blacklisted by the NSA, so I suppose it works then? I wrote some custom apps that use 'key-interleaving' so that as I type, the key is backspaced, replaced by anot
12.
▲
You Can’t Sacrifice Partition Tolerance (2010)
(codahale.com)
43 points
by
xrorre
10y ago
|
21 comments
13.
▲
by
xrorre
11y ago
The Apple situation annoys me because it's no longer about the web. It's about breaking crypto on a device which is vendor-locked. The same thing as breaking homegrown crypto, or DVD crypto; easy and trivial. The fact that Apple d
14.
▲
Cool URIs don't change
(w3.org)
1 points
by
xrorre
11y ago
|
0 comments
15.
▲
by
xrorre
11y ago
> Well the security they engender is mostly physical security i.e. not getting blown up by terrorists while the security they want to breach is information security. This is exactly my point. They use the terrorist strawman to frame thei
16.
▲
by
xrorre
11y ago
Better wording of a back door is donwgraded security. For an institution whose sole purpose is to engender security, they do the opposite. It's like saying they have better, more expensive guns than the rest of us. Which collectively i
17.
▲
by
xrorre
11y ago
The second occurrence is not only inevitable, it refutes the notion of a door in the first place, which is supposed to be fully opened at some stage for long periods, not temporarily opened in-case-of-emergency, or half-shut just-in-case.
18.
▲
The Open API Initiative
(openapis.org)
80 points
by
xrorre
11y ago
|
21 comments
19.
▲
Fractal Characterization in Out
(overthinkingit.com)
1 points
by
xrorre
11y ago
|
0 comments